De-Anonymizing Web Communities with Gravatar
rgov.org
rgov.org
I think that works, but I try not to think about crypto at three in the morning, or at all really.
EDIT: Also, a consumer site could implement this themselves with a simple proxy server. They could even open up the service to other sites.
"http://www.gravatar.com/avatar/#{MD5::md5(email.downcase)}"
If it wasn't that easy, I'd probably consider just doing something else. Maybe just have it use a stronger hashing algo? ...have it use a stronger hashing algo?
The strength of the hashing algorithm is ancillary to this vulnerability. The OP was able to resolve the emails because they had a predictable format.Then again, crypto is not my strong point, so I should probably stop talking.
Moral of the story: simply hashing emails is not enough if you're going to display them publicly. It's trivial to use a salt and prevent such an attack.
However, a user can protect herself by "salting" her own email with an address tag. For example, provide tom+ES85jFxz@rpi.edu as your address instead of tom@rpi.edu.
md5("comment+sitename1@mydomain.com") != md5("comment+sitename2@mydomain.com")
However, it is really interesting to see the amount of spam I get sent to certain 'snowflake' email addresses I have only ever used to submit a comment to top well known blogs. Shows how much database hacking for email harvest goes on.If whatever service I am using can't work without gravatar, they will have to see a generic picture.
HTML5 'email' fields should hopefully mean this'll be fixed in approximately 30 years.
made me laugh. since then i ignored the service as they are obvious just a bunch of script kiddies.
to be honest - the only obsticle for such a service is server redundancy. nothing special about it. besides that its now a obsolete service since every major site offers oauth.